PT-2026-73159 · Scriban · Scriban
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Scriban versions prior to 7.0.0
Description
The software fails to clear the
CachedTemplates dictionary when the TemplateContext.Reset() function is called, which allows cached templates to persist across reused contexts. This can be exploited through request-dependent ITemplateLoader implementations, enabling unauthorized access to template content from previous renders without re-triggering the TemplateLoader.Load() function.Recommendations
Update to version 7.0.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scriban